Bugsalert.com
Security News about Viruses, Spyware,
Trojans, Malware, XSS attacks.

CVE-2008-4343 (chilkat_xml_activex_control)

BugsAlert Home > CVE-2008-4343 (chilkat_xml_activex_control)
 
 

The Chilkat XML ChilkatUtil.CkData.1 ActiveX control (ChilkatUtil.dll) 3.0.3.0 and earlier allows remote attackers to create, overwrite, and modify arbitrary files for execution via a call to the (1) SaveToFile, (2) SaveToTempFile, or (3) AppendBinary method. NOTE: this issue might only be exploitable in limited environments or non-default browser settings. NOTE: this can be leveraged for remote code execution by accessing files using hcp:// URLs.




Original Source: http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2008-4343

Learn more about CVE-2008-4343 (chilkat_xml_activex_control)
 
Tags: cve-2008-4343 chilkat xml activex control

Related Items

      e107 Plugin EasyShop (category_id) Blind SQL Injection Exploit

      Novell ZENworks Patch Management Insecure Temporary Files

      Bugtraq: Security and Hacking Papers - Updated!

      CVE-2008-4393 (kontiki_delivery_management_system)

      CVE-2008-2981 (homeph_design)

      New Old Bills: The Rechnung Revivals

      MS07-061 ? Critical: Vulnerability in Windows URI Handling Could Allow Remote Code Execution (943460)

 

Pixel